
crowdsec
Open-source IDS/IPS and WAF engine that analyzes logs and HTTP requests to detect and block malicious IPs, leveraging a crowdsourced community…

Open-source IDS/IPS and WAF engine that analyzes logs and HTTP requests to detect and block malicious IPs, leveraging a crowdsourced community…

Detect Tactics, Techniques & Combat Threats

APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of…

An Active Defense and EDR software to empower Blue Teams

Open-source Windows forensics engine that acquires, parses, and correlates artifacts (MFT, USN, Registry, etc.) to reconstruct timelines with…

The purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious…

analyze a web-based network traffic 🕶 to detect central command and control servers

Basic log analysis tool to detect impossible travel via IP address geographic information

A Simple Log4j Indicator of Compromise Linux Detector

Bro analyzer that detects Google's QUIC protocol

Quick One Line Powershell scripts to detect for webshells, possible zips, and logs.

A Zeek OpenVPN protocol analyzer plugin.

This repository contains Velociraptor artifact and Chainsaw rules to help detect Microsoft Remote Access VPN activity

Analyzes Nginx access logs to detect SQL injection, scanner tools, webshells, and exploitation attempts, aiding system administrators in server…



Scans Windows IIS logs for signs of CVE-2025-53770 & CVE-2025-53771

Blue Team lab focused on analyzing Apache web access logs to detect directory brute forcing and web scanning activity.